
Third-Party Security Manager
Posted 10 hours ago

Posted 10 hours ago
This is a fully remote position, open to applicants in United States.
• Lead and enhance the organization's Third-Party Risk Management (TPRM) program.
• Develop, sustain, and continually refine TPRM frameworks, policies, standards, and procedures.
• Establish risk-based processes for onboarding, reviewing, monitoring, and offboarding third parties.
• Define methodologies for vendor risk assessments and criteria for risk scoring.
• Align third-party risk practices with standards such as NIST, SOC 2, ISO 27001, FFIEC, GLBA, PCI-DSS, as well as relevant privacy regulations.
• Conduct assessments of security, privacy, operational, compliance, and business continuity risks for vendors.
• Review vendor security documentation, which includes SOC reports, ISO certifications, penetration test reports, vulnerability management reports, security questionnaires, and continuity plans.
• Identify control gaps and coordinate remediation strategies with vendors and stakeholders.
• Evaluate dependencies on fourth-party providers and concentration risks.
• Maintain inventories of third-party relationships and their associated risk ratings.
• Develop processes for the continuous monitoring of critical and high-risk vendors.
• Monitor vendor security ratings, threat intelligence, breach activities, financial health, and compliance status.
• Track remediation efforts and facilitate regular vendor reviews and reassessments.
• Collaborate with Procurement, Legal, Privacy, Compliance, business owners, and Information Security during vendor selection and contract negotiations.
• Provide guidance on vendor risk to business leaders.
• Present findings and recommendations regarding vendor risk to leadership, risk committees, and executive management.
• Support internal and external audits concerning vendor management controls.
• Establish security and privacy contractual obligations in collaboration with Legal and Procurement.
• Review and suggest contract language related to security controls, data protection, breach notification, audit rights, business continuity, and regulatory compliance.
• Ensure that vendor agreements incorporate relevant security, privacy, and reporting obligations.
• Develop and maintain TPRM dashboards, KPIs, and executive reporting.
• Track assessment volumes, remediation progress, risk trends, and metrics of program maturity.
• Regularly report to Information Security leadership, Enterprise Risk Management, and audit committees.
• Support initiatives for risk quantification and business impact analysis.
• Mentor and guide less experienced professional contributors.
• Bachelor's Degree directly related to the position or equivalent is preferred.
• A minimum of five years of relevant experience is required.
• At least three years of supervisory or leadership experience is necessary.
• Excellent verbal and written communication skills are essential.
• Highly organized and detail-oriented approach is required.
• Ability to thrive in a fast-paced, metrics-driven environment.
• Proficiency in Microsoft Office Suite, including Word and Excel, Wiki, collaborative cloud-based tools, and third-party software applications.
• A strong commitment to company values is expected.
• Availability to work Monday through Friday during standard business hours.
• Travel requirements of 5% or less.
• Work is primarily sedentary, involving frequent use of a computer keyboard and mouse.
• Capability to learn new tasks, retain processes, maintain focus, complete tasks independently, and make timely decisions.
• Ability to adhere to and apply established process protocols in a timely manner.
• Medical insurance.
• Dental insurance.
• Vision insurance.
• Life insurance.
• AD&D insurance.
• LTD insurance.
• 401(k) with employer match.
• Competitive compensation.
• Pleasant work environment.
Agile Defense
Stripe
Cambiar Education
Docker, Inc
Get handpicked remote jobs straight to your inbox weekly.